This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Network Connection Initiated To Cloudflared Tunnels Domains
Original Source:
[Sigma source]
Title:
Network Connection Initiated To Cloudflared Tunnels Domains
Status:
test
Description:
Detects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
-https://defr0ggy.github.io/research/Abusing-Cloudflared-A-Proxy-Service-To-Host-Share-Applications/
-https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/
-Internal Research
Author:
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems)
Date:
2024-05-27
modified:
None
Tags:
-'attack.exfiltration'
-'attack.command-and-control'
-'attack.t1567'
-'attack.t1572'
Logsource:
category: network_connection
product: windows
Detection:
selection:
Initiated
:
'true'
DestinationHostname|endswith
:
-'.v2.argotunnel.com'
-'protocol-v2.argotunnel.com'
-'trycloudflare.com'
-'update.argotunnel.com'
condition
:
selection
Falsepositives:
-Legitimate use of cloudflare tunnels will also trigger this.
Level:
medium